REVIEW 3 major objections 5 minor 70 references
Unconsidered Installations: Discovering IoT Deployments in the IPv6 Internet
T0 review · 3 major / 5 minor · reviewed 2026-08-12 · deepseek-v4-flash
Pith's one-line read IPv6-reachable IoT deployments can be found efficiently, and they are about as insecure as IPv4 ones.
desk verdict First systematic IPv6 IoT discovery study, with a post-hoc generator-coverage claim that needs external validation before it becomes a recipe. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing machinery is the combination of seedlists and IPv6 address generators, with per-address origin tracking to attribute every found deployment to its source. Seedlists (the TUM hitlist, DNS AAAA records from ICANN zone files, and reverse-DNS/certificate data from a prior IPv4 scan) provide real, currently used addresses; generators such as 6Scan (which uses regional encoding and active probing to propose new search directions) and 6Graph (which mines address patterns as high-density regions in a graph) expand from those seeds into unlisted addresses. Origin tracking is what lets the paper rank generators and claim that two generators plus all hitlists recover 95% of deployments, since without it the overlap between generator outputs is invisible.
What would settle it
Deploy a set of IoT test services at freshly allocated IPv6 addresses drawn from sources outside the three seedlists (for example, brand-new ISP prefixes or addresses from public NTP pools), then run the paper's recommended pipeline; if the pipeline finds far fewer than 95% of these known deployments, or if a full eleven-generator run finds many deployments the subset misses on a later scan date, the central coverage claim is refuted.
Extended reading notes
Core claim
The central claim is that a practical recipe exists for discovering IoT deployments in the IPv6 Internet, and that applying it reveals a security situation as bad as IPv4's. The authors scanned roughly 14 billion IPv6 addresses generated from three seed sources and eleven generators, validated responders at the application layer, and identified 6,658 IoT deployments: 6,650 backend services (AMQP, MQTT) and only 8 device-side services (OPC UA, CoAP). Source tracing shows the TUM seedlist supplies the most deployments, the openly filtered version of that list is unsuitable because Web/ICMP liveness filtering removes IoT addresses, and generator output adds 768 deployments beyond the seedlists. The efficiency claim is that 6Scan and 6Graph on DNS (www) plus all available hitlists cover 95% of the found deployments, so future studies can skip the remaining generators. Security-wise, the paper claims IPv6 deployments mirror IPv4: 6.2% versus 6.3% use (D)TLS, 39% versus 48% lack access control, and IPv6 deployments are more likely to accept deprecated ciphers and short RSA keys, despite a larger share supporting TLS 1.3 (63% versus 35%).
Load-bearing premise
The load-bearing assumption is that the 6,658 discovered deployments represent all IPv6-reachable IoT deployments, so the coverage percentages and security figures generalize; the paper itself concedes it cannot reliably estimate what portion of installations it covered and that the cloud-provider focus may bias the security results.
Editorial extensions
If this is right
- Future IPv6 IoT studies can run the TUM unfiltered list, DNS (www) seeds, and the v4-derived list through 6Scan and 6Graph and expect to see about 95% of the deployments a full eleven-generator pipeline would find, with far less compute.
- Internet-wide security assessments that stop at IPv4 miss a population of deployments, including 89 deployments in ASes with no IPv4 findings.
- IPv6 deployments are newer but not better secured, so IPv6-specific hardening and monitoring are needed, not just a hope that modern stacks fix legacy mistakes.
- Researchers should not rely on the openly filtered TUM hitlist for IoT scanning, because its Web/ICMP reachability filter removes addresses that still run IoT services.
- The four-protocol finding that only 6.2% use TLS and 39% lack access control gives a baseline for measuring future IPv6 IoT security.
Reading between the lines
- The paper does not test this, but if the 95% coverage result reflects IPv6 address structure rather than IoT-specific quirks, the same two-generator-plus-hitlists recipe may also improve IPv6 discovery for other non-Web services beyond IoT, such as industrial protocols or email servers.
- Because the found IPv6 deployments skew toward content and cloud networks, the security fractions may understate the risk in home or ISP-run deployments, which the paper notes could bias results; an IPv6 scan starting from ISP-heavy seedlists would test this.
- The paper does not claim this, but the coverage result is relative to the 6,658 deployments this pipeline found, not to the unknown total IPv6 IoT population; if systematically missed deployments differ in security, the headline 39% and 6.2% numbers could shift.
- A direct extension would be to run the recommended subset and the full pipeline side by side on a fresh date and measure overlap, turning the 95% statement into a reproducible benchmark for future scan-strategy papers.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper proposes a methodology to discover IPv6-reachable IoT deployments by combining three seedlists (TUM hitlist, DNS AAAA records, and IPv4 scan data) with eleven IPv6 address generators, then scanning four IoT protocols (AMQP, MQTT, OPC UA, CoAP) on standard and (D)TLS ports. The authors report 6,658 valid IPv6 deployments, trace their provenance across the seedlists and generators, and claim that two generators (6Scan and 6Graph on DNS (www)) together with all seedlists cover 95% of the found deployments. They also compare security configurations with IPv4, finding that only 39% of IPv6 deployments have access control and 6.2% use (D)TLS. The paper releases the scanning tools publicly.
Significance. The paper addresses a genuine gap in Internet-wide IoT studies, which have so far focused almost exclusively on IPv4, and it provides a reproducible combination of established IPv6 hitlists and generators. The validation pipeline—TCP and (D)TLS handshakes plus protocol-conformant application-layer requests—is sensible, and the authors take care with deduplication, aliasing, and ethical scanning constraints. If taken as a descriptive account of the discovered sample, the paper offers useful quantitative evidence about the findability, provenance, and security configuration of IPv6 IoT backends, and the open-source tooling is a valuable community resource. The main reservation is that the central prescriptive claim, that two generators suffice, is derived from the same dataset used to select those generators, so its external validity is not yet established.
major comments (3)
- [Section IV, Fig. 2] The '95% coverage' claim is computed on the same dataset that was used to select 6Scan and 6Graph as the best two generators. Because the selection is made after observing the full outcome matrix across all eleven generators and five seedlists, the 95% figure is an in-sample statistic rather than a validated prediction for a future scan campaign. To support the paper's guidance for future IPv6 IoT studies, please add a holdout validation (for example, select generators on one per-protocol scan date and evaluate on another date, or perform a leave-one-seedlist-out cross-validation) or explicitly reposition the claim as a descriptive summary of this campaign rather than a recipe for future studies.
- [Abstract and Section V] The security statistics (39% no access control, 6.2% TLS) are presented in the abstract as general characteristics of 'deployments,' but they are computed from a sample in which 6,650 of 6,658 deployments are AMQP/MQTT backends (Section III-B), and the paper itself notes (Section V) that the concentration in content/cloud ASes 'might bias our result.' In addition, Section VI explicitly disclaims any reliable estimate of what fraction of the IPv6 installation space was covered. Please qualify all security claims as applying to the discovered sample of AMQP/MQTT backends, or add a robustness analysis stratified by AS type and protocol to provide a quantitative basis for broader generalization.
- [Section IV] The paper does not show the exact computation behind the 95% coverage claim. Please define it as (seedlist-only deployments plus additional deployments found only by the chosen generators) divided by total valid deployments, and ideally present an incremental coverage curve so readers can verify how the 95% is reached. Without this, it is difficult to assess how much of the claimed sufficiency is due to the two generators versus the already-strong seedlist baseline of 5,890 deployments.
minor comments (5)
- [Section IV] The sentence 'With 24 additionally found deployments, information from IPv4 scans have still a low, but the comparably highest gain in comparison to the TUM list' is hard to parse; please rephrase for clarity.
- [Figure 1] Figure 1 is dense and the three panels are not clearly labeled in the caption; please enlarge the fonts and add explicit panel descriptions (e.g., 'Base', 'Gain', 'Generators').
- [Section III-A3] Please state explicitly which generators were run with reduced input sizes beyond 6VecLM, and discuss how such reductions might bias the generated address sets.
- [Section III-B] The phrase 'operators "hide" several non-IoT-related services' attributes intent to observed behavior; consider rewording to 'indicates that many non-IoT services are reachable on these ports.'
- [Table II] The header cells in Table II contain confusing line breaks and stray labels such as '1 Distinct'; please reformat the table so that the column structure is immediately readable.
Circularity Check
No construction-level circularity; the 95% coverage claim is in-sample and explicitly limited, but the generator recommendation lacks temporal holdout.
full rationale
The paper's load-bearing claims are direct measurements rather than derived predictions. The 6658 deployments are produced by scanning seedlists plus generator outputs, and the security fractions (39% no access control, 6.2% TLS) come from direct handshakes on those deployments. Section IV's 95% claim is explicitly about 'all our found deployments' and is therefore a retrospective summary of the same corpus used to rank generators; Section VI acknowledges that 'All IPv6-wide studies, including ours, cannot reliably estimate which portion of installations they covered.' That is a real in-sample selection caveat for the practical recipe (6Scan and 6Graph on DNS (www) plus all hitlists), but it is a holdout/validation concern, not a definitional reduction: the paper does not rename a fitted parameter as a prediction. Self-citations to the authors' prior OPC UA and TLS work ([7], [19]) supply measurement methodology and background, while [21] is an artifact release; none carries the central argument. The IPv4 comparison is re-measured in the same campaign, so the 'similar security issues' result is independently obtained. No equation or construction step equates an output to an input, so no circular step is present.
Assumptions & free parameters
assumptions (4)
- domain assumption The four selected protocols (AMQP, MQTT, OPC UA, CoAP) and their standard/secure ports are representative of IoT deployments.
- domain assumption The 11 address generators, configured as in their publications, behave as described and their outputs can be scanned in the given timeframe.
- domain assumption The three seedlists (TUM hitlist, DNS zone AAAA records, IPv4-scan-derived addresses) are good sources and random sampling of larger seedlists does not bias generator outputs.
- domain assumption ZMapv6 and zgrab2 correctly identify open ports and validate IoT protocol handshakes.
Cite this review
Pith. "Pith review of Unconsidered Installations: Discovering IoT Deployments in the IPv6 Internet." pith.science (2026). https://pith.science/paper/3HWHYRU5
@misc{pith2026241113799,
author = {Pith},
title = {Pith review of: Unconsidered Installations: Discovering IoT Deployments in the IPv6 Internet},
year = {2026},
howpublished = {\url{https://pith.science/paper/3HWHYRU5}},
note = {Machine review of arXiv:2411.13799}
}
read the original abstract
Internet-wide studies provide extremely valuable insight into how operators manage their Internet of Things (IoT) deployments in reality and often reveal grievances, e.g., significant security issues. However, while IoT devices often use IPv6, past studies resorted to comprehensively scan the IPv4 address space. To fully understand how the IoT and all its services and devices is operated, including IPv6-reachable deployments is inevitable-although scanning the entire IPv6 address space is infeasible. In this paper, we close this gap and examine how to best discover IPv6-reachable IoT deployments. To this end, we propose a methodology that allows combining various IPv6 scan direction approaches to understand the findability and prevalence of IPv6-reachable IoT deployments. Using three sources of active IPv6 addresses and eleven address generators, we discovered 6658 IoT deployments. We derive that the available address sources are a good starting point for finding IoT deployments. Additionally, we show that using two address generators is sufficient to cover most found deployments and save time as well as resources. Assessing the security of the deployments, we surprisingly find similar issues as in the IPv4 Internet, although IPv6 deployments might be newer and generally more up-to-date: Only 39% of deployments have access control in place and only 6.2% make use of TLS inviting attackers, e.g., to eavesdrop sensitive data.
Figures
Reference graph
Works this paper leans on
-
[1]
A systematic literature review on Internet of things in education: Benefits and challenges,
M. Kassab, J. DeFranco, and P. Laplante, “A systematic literature review on Internet of things in education: Benefits and challenges,” Journal of Computer Assisted Learning , vol. 36, no. 2, pp. 115–127, 2020
work page 2020
-
[2]
Industrial internet of things: Recent advances, enabling technologies and open challenges,
W. Z. Khan, M. H. Rehman, H. M. Zangoti, M. K. Afzal, N. Armi, and K. Salah, “Industrial internet of things: Recent advances, enabling technologies and open challenges,”Computers & Electrical Engineering, vol. 81, 2020
work page 2020
-
[3]
Dis- tributed Configuration, Authorization and Management in the Cloud- based Internet of Things,
M. Henze, B. Wolters, R. Matzutt, T. Zimmermann, and K. Wehrle, “Dis- tributed Configuration, Authorization and Management in the Cloud- based Internet of Things,” in Proceedings of the 2017 IEEE Interna- tional Conference on Trust, Security and Privacy in Computing and Communications (TrustCom ’17) . IEEE, 2017, pp. 185–192
work page 2017
-
[4]
F. Maggi, R. V osseler, and D. Quarta, “The Fragility of Industrial IoT’s Data Backbone: Security and Privacy Issues in MQTT and CoAP Protocols,” Trend Micro Inc., Tech. Rep., 2018
work page 2018
-
[5]
The Multiple Roles That IPv6 Ad- dresses Can Play in Today’s Internet,
M. Piraux, T. Barbette, N. Rybowski, L. Navarre, T. Alfroy, C. Pelsser, F. Michel, and O. Bonaventure, “The Multiple Roles That IPv6 Ad- dresses Can Play in Today’s Internet,” ACM SIGCOMM Computer Communication Review, vol. 52, no. 3, pp. 10–18, 2022
work page 2022
-
[6]
Internet Addressing: Measuring Deployment of IPv6,
K. Perset, “Internet Addressing: Measuring Deployment of IPv6,” Organisation for Economic Co-operation and Development (OECD), OECD Digital Economy Papers 172, 2010
work page 2010
-
[7]
Easing the Conscience with OPC UA: An Internet-Wide Study on Insecure Deployments,
M. Dahlmanns, J. Lohm ¨oller, I. B. Fink, J. Pennekamp, K. Wehrle, and M. Henze, “Easing the Conscience with OPC UA: An Internet-Wide Study on Insecure Deployments,” in Proceedings of the ACM Internet Measurement Conference (IMC ’20) . ACM, 2020, pp. 101–110
work page 2020
-
[8]
Z. Durumeric, F. Li, J. Kasten, J. Amann, J. Beekman, M. Payer, N. Weaver, D. Adrian, V . Paxson, M. Bailey, and J. A. Halderman, “The Matter of Heartbleed,” in Proceedings of the 2014 Conference on Internet Measurement Conference (IMC ’14) . ACM, 2014, pp. 475– 488
work page 2014
Show all 70 references
-
[9]
On the Interplay between TLS Certificates and QUIC Performance,
M. Nawrocki, P. F. Tehrani, R. Hiesgen, J. M ¨ucke, T. C. Schmidt, and M. W ¨ahlisch, “On the Interplay between TLS Certificates and QUIC Performance,” in Proceedings of the 18th International Conference on Emerging Networking EXperiments and Technologies (CoNEXT ’22) . ACM, 2...
2022
-
[10]
Zippier ZMap: Internet-Wide Scanning at 10 Gbps,
D. Adrian, Z. Durumeric, G. Singh, and J. A. Halderman, “Zippier ZMap: Internet-Wide Scanning at 10 Gbps,” in Proceedings of the 8th USENIX Workshop on Offensive Technologies (WOOT ’14) . USENIX Association, 2014
2014
-
[11]
Clusters in the Expanse: Un- derstanding and Unbiasing IPv6 Hitlists,
O. Gasser, Q. Scheitle, P. Foremski, Q. Lone, M. Korczy ´nski, S. D. Strowes, L. Hendriks, and G. Carle, “Clusters in the Expanse: Un- derstanding and Unbiasing IPv6 Hitlists,” in Proceedings of the 2018 Internet Measurement Conference (IMC ’18) . ACM, 2018, pp. 364– 378
2018
-
[12]
Rusty Clusters? Dusting an IPv6 Research Foundation,
J. Zirngibl, L. Steger, P. Sattler, O. Gasser, and G. Carle, “Rusty Clusters? Dusting an IPv6 Research Foundation,” in Proceedings of the 22nd ACM Internet Measurement Conference (IMC ’22) . ACM, 2022, pp. 395–409
2022
-
[13]
6Graph: A graph-theoretic approach to address pattern mining for Internet-wide IPv6 scanning,
T. Yang, B. Hou, Z. Cai, K. Wu, T. Zhou, and C. Wang, “6Graph: A graph-theoretic approach to address pattern mining for Internet-wide IPv6 scanning,” Computer Networks, vol. 203, 2022
2022
-
[14]
DET: Enabling Efficient Probing of IPv6 Active Addresses,
G. Song, J. Yang, Z. Wang, L. He, J. Lin, L. Pan, C. Duan, and X. Quan, “DET: Enabling Efficient Probing of IPv6 Active Addresses,” IEEE/ACM Transactions on Networking, vol. 30, no. 4, pp. 1629–1643, 2022
2022
-
[15]
6Scan: A High- Efficiency Dynamic Internet-Wide IPv6 Scanner With Regional Encod- ing,
B. Hou, Z. Cai, K. Wu, T. Yang, and T. Zhou, “6Scan: A High- Efficiency Dynamic Internet-Wide IPv6 Scanner With Regional Encod- ing,” IEEE/ACM Transactions on Networking , 2023
2023
-
[16]
Target Acquired? Evaluating Target Generation Algorithms for IPv6,
L. Steger, L. Kuang, J. Zirngibl, G. Carle, and O. Gasser, “Target Acquired? Evaluating Target Generation Algorithms for IPv6,” in Pro- ceedings of the 15th International Workshop on Traffic Monitoring and Analysis (TMA ’23) . IFIP, 2023
2023
-
[17]
Deep Dive into the IoT Backend Ecosystem,
S. J. Saidi, S. Matic, O. Gasser, G. Smaragdakis, and A. Feldmann, “Deep Dive into the IoT Backend Ecosystem,” in Proceedings of the 22nd ACM Internet Measurement Conference (IMC ’22) . ACM, 2022, pp. 488–503
2022
-
[18]
Analyzing IoT Hosts in the IPv6 Internet,
P. Jose, S. J. Saidi, and O. Gasser, “Analyzing IoT Hosts in the IPv6 Internet,” arXiv:2307.09918, 2023
2023 arXiv
-
[19]
Missed Opportunities: Measuring the Untapped TLS Support in the Industrial Internet of Things,
M. Dahlmanns, J. Lohm ¨oller, J. Pennekamp, J. Bodenhausen, K. Wehrle, and M. Henze, “Missed Opportunities: Measuring the Untapped TLS Support in the Industrial Internet of Things,” in Proceedings of the 17th ACM ASIA Conference on Computer and Communications Security (ASIACCS...
2022
-
[20]
Open for Hire: Attack Trends and Misconfiguration Pitfalls of IoT Devices,
S. Srinivasa, J. M. Pedersen, and E. Vasilomanolakis, “Open for Hire: Attack Trends and Misconfiguration Pitfalls of IoT Devices,” in Pro- ceedings of the 21st ACM Internet Measurement Conference (IMC ’21) . ACM, 2021, pp. 195–215
2021
-
[21]
IPv6 Scanning Tools,
COMSYS, “IPv6 Scanning Tools,” https://github.com/COMSYS/ ipv6-scanning, 2024
2024
-
[22]
IPv6 Implications for Network Scanning,
T. Chown, “IPv6 Implications for Network Scanning,” IETF RFC 5157, 2008
2008
-
[23]
Network Reconnaissance in IPv6 Networks,
F. Gont and T. Chown, “Network Reconnaissance in IPv6 Networks,” IETF RFC 7707, 2016
2016
-
[24]
Enumerating Active IPv6 Hosts for Large-Scale Security Scans via DNSSEC-Signed Reverse Zones,
K. Borgolte, S. Hao, T. Fiebig, and G. Vigna, “Enumerating Active IPv6 Hosts for Large-Scale Security Scans via DNSSEC-Signed Reverse Zones,” in Proceedings of the 2018 IEEE Symposium on Security and Privacy (SP ’18) . IEEE, 2018, pp. 770–784
2018
-
[25]
Scanning the IPv6 Internet: Towards a Comprehensive Hitlist,
O. Gasser, Q. Scheitle, S. Gebhard, and G. Carle, “Scanning the IPv6 Internet: Towards a Comprehensive Hitlist,” in Proceedings of the 8th International Workshop on Traffic Monitoring and Analysis (TMA ’16) . IFIP, 2016
2016
-
[26]
Something from Nothing (There): Collecting Global IPv6 Datasets from DNS,
T. Fiebig, K. Borgolte, S. Hao, C. Kruegel, and G. Vigna, “Something from Nothing (There): Collecting Global IPv6 Datasets from DNS,” in Proceedings of the 18th International Conference on Passive and Active Measurement (PAM ’17), vol. 10176. Springer, 2017, pp. 30–43
2017
-
[27]
It’s over 9000: Analyzing Early QUIC Deployments with the Stan- dardization on the Horizon,
J. Zirngibl, P. Buschmann, P. Sattler, B. Jaeger, J. Aulbach, and G. Carle, “It’s over 9000: Analyzing Early QUIC Deployments with the Stan- dardization on the Horizon,” in Proceedings of the 21st ACM Internet Measurement Conference (IMC ’21) . ACM, 2021, pp. 261–275
2021
-
[28]
Fast IPv6 Network Periphery Discovery and Security Implications,
X. Li, B. Liu, X. Zheng, H. Duan, Q. Li, and Y . Huang, “Fast IPv6 Network Periphery Discovery and Security Implications,” in Proceed- ings of the 2021 51st Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN ’21). IEEE, 2021, pp. 88–100
2021
-
[29]
Towards the Construction of Global IPv6 Hitlist and Efficient Probing of IPv6 Ad- dress Space,
G. Song, L. He, Z. Wang, J. Yang, T. Jin, J. Liu, and G. Li, “Towards the Construction of Global IPv6 Hitlist and Efficient Probing of IPv6 Ad- dress Space,” in Proceedings of the 2020 IEEE/ACM 28th International Symposium on Quality of Service (IWQoS ’20) . IEEE, 2020
2020
-
[30]
On Reconnais- sance with IPv6: A Pattern-Based Scanning Approach,
J. Ullrich, P. Kieseberg, K. Krombholz, and E. Weippl, “On Reconnais- sance with IPv6: A Pattern-Based Scanning Approach,” in Proceedings of the 2015 10th International Conference on Availability, Reliability and Security (ARES ’15) . IEEE, 2015, pp. 186–192
2015
-
[31]
Entropy/IP: Uncovering Struc- ture in IPv6 Addresses,
P. Foremski, D. Plonka, and A. Berger, “Entropy/IP: Uncovering Struc- ture in IPv6 Addresses,” in Proceedings of the 2016 ACM Internet Measurement Conference (IMC ’16) . ACM, 2016, pp. 167–181
2016
-
[32]
Target Generation for Internet-Wide IPv6 Scanning,
A. Murdock, F. Li, P. Bramsen, Z. Durumeric, and V . Paxson, “Target Generation for Internet-Wide IPv6 Scanning,” in Proceedings of the 2017 Internet Measurement Conference (IMC ’17) . ACM, 2017, pp. 242–253
2017
-
[33]
An Effective Target Address Generation Method for IPv6 Address Scan,
G. Zheng, X. Xu, and C. Wang, “An Effective Target Address Generation Method for IPv6 Address Scan,” in Proceedings of the 2020 IEEE 6th International Conference on Computer and Communications (ICCC ’20). IEEE, 2020, pp. 73–77
2020
-
[34]
6GCV AE: Gated Convolutional Varia- tional Autoencoder for IPv6 Target Generation,
T. Cui, G. Gou, and G. Xiong, “6GCV AE: Gated Convolutional Varia- tional Autoencoder for IPv6 Target Generation,” in Proceedings of the 24th Pacific-Asia Conference on Advances in Knowledge Discovery and Data Mining (PAKDD ’20) , vol. 12084. Springer, 2020, pp. 609–622
2020
-
[35]
6VecLM: Language Modeling in Vector Space for IPv6 Target Generation,
T. Cui, G. Xiong, G. Gou, J. Shi, and W. Xia, “6VecLM: Language Modeling in Vector Space for IPv6 Target Generation,” in Proceedings of the European Conference on Machine Learning and Knowledge Discovery in Databases: Applied Data Science Track (ECML PKDD ’20), vol. 12460. Spr...
2021
-
[36]
6GAN: IPv6 Multi-Pattern Target Generation via Generative Adversarial Nets with Reinforcement Learning,
T. Cui, G. Gou, G. Xiong, C. Liu, P. Fu, and Z. Li, “6GAN: IPv6 Multi-Pattern Target Generation via Generative Adversarial Nets with Reinforcement Learning,” in Proceedings of the 40th IEEE Conference on Computer Communications (INFOCOM ’21) . IEEE, 2021
2021
-
[37]
6Forest: An Ensemble Learning- based Approach to Target Generation for Internet-wide IPv6 Scanning,
T. Yang, Z. Cai, B. Hou, and T. Zhou, “6Forest: An Ensemble Learning- based Approach to Target Generation for Internet-wide IPv6 Scanning,” in Proceedings of the 41st IEEE Conference on Computer Communica- tions (IEEE INFOCOM ’22) . IEEE, 2022, pp. 1679–1688
2022
-
[38]
6Tree: Efficient dynamic discovery of active addresses in the IPv6 address space,
Z. Liu, Y . Xiong, X. Liu, W. Xie, and P. Zhu, “6Tree: Efficient dynamic discovery of active addresses in the IPv6 address space,” Computer Networks, vol. 155, pp. 31–46, 2019
2019
-
[39]
6Hit: A Reinforcement Learning-based Approach to Target Generation for Internet-wide IPv6 Scanning,
B. Hou, Z. Cai, K. Wu, J. Su, and Y . Xiong, “6Hit: A Reinforcement Learning-based Approach to Target Generation for Internet-wide IPv6 Scanning,” in Proceedings of the 40th IEEE Conference on Computer Communications (INFOCOM ’21) . IEEE, 2021
2021
-
[40]
AddrMiner: A Comprehensive Global Active IPv6 Address Discovery System,
G. Song, J. Yang, L. He, Z. Wang, G. Li, C. Duan, Y . Liu, and Z. Sun, “AddrMiner: A Comprehensive Global Active IPv6 Address Discovery System,” in Proceedings of the 2022 USENIX Annual Technical Con- ference (ATC ’22) . USENIX Association, 2022, pp. 309–326
2022
-
[41]
Third Time’s Not a Charm: Exploiting SNMPv3 for Router Fingerprinting,
T. Albakour, O. Gasser, R. Beverly, and G. Smaragdakis, “Third Time’s Not a Charm: Exploiting SNMPv3 for Router Fingerprinting,” in Pro- ceedings of the 21st ACM Internet Measurement Conference (IMC ’21) . ACM, 2021, pp. 150–164
2021
-
[42]
Speedtrap: Internet-Scale IPv6 Alias Resolution,
M. Luckie, R. Beverly, W. Brinkmeyer, and k. claffy, “Speedtrap: Internet-Scale IPv6 Alias Resolution,” in Proceedings of the 2013 Internet Measurement Conference (IMC ’13) . ACM, 2013, pp. 119– 126
2013
-
[43]
IPv6 Alias Resolution via Induced Fragmentation,
R. Beverly, W. Brinkmeyer, M. Luckie, and J. P. Rohrer, “IPv6 Alias Resolution via Induced Fragmentation,” in Proceedings of the 14th International Conference on Passive and Active Measurement (PAM ’13), vol. 7799. Springer, 2013, pp. 155–165
2013
-
[44]
Alias Resolution Based on ICMP Rate Limiting,
K. Vermeulen, B. Ljuma, V . Addanki, M. Gouel, O. Fourmaux, T. Fried- man, and R. Rejaie, “Alias Resolution Based on ICMP Rate Limiting,” in Proceedings of the 21st International Conference Passive and Active Measurement (PAM ’20), vol. 12048. Springer, 2020, pp. 231–248
2020
-
[45]
APPLE: Alias Pruning by Path Length Estimation,
A. Marder, “APPLE: Alias Pruning by Path Length Estimation,” in Proceedings of the 21st International Conference Passive and Active Measurement (PAM ’20), vol. 12048. Springer, 2020, pp. 249–263
2020
-
[46]
UAv6: Alias Resolution in IPv6 Using Unused Addresses,
R. Padmanabhan, Z. Li, D. Levin, and N. Spring, “UAv6: Alias Resolution in IPv6 Using Unused Addresses,” in Proceedings of the 16th International Conference on Passive and Active Measurement (PAM ’15), vol. 8995. Springer, 2015, pp. 136–148
2015
-
[47]
Pushing Alias Resolution to the Limit,
T. Albakour, O. Gasser, and G. Smaragdakis, “Pushing Alias Resolution to the Limit,” in Proceedings of the 2023 ACM Internet Measurement Conference (IMC ’23) , Oct. 2023
2023
-
[48]
A Search Engine Backed by Internet-Wide Scanning,
Z. Durumeric, D. Adrian, A. Mirian, M. Bailey, and J. A. Halderman, “A Search Engine Backed by Internet-Wide Scanning,” in Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security (CCS ’15) . ACM, 2015, pp. 542–553
2015
-
[49]
Censys, “Censys,” https://www.censys.io, 2023
2023
-
[50]
Quantitatively Assessing and Visualising Industrial System Attack Surfaces,
´E. P. Leverett, “Quantitatively Assessing and Visualising Industrial System Attack Surfaces,” Master’s thesis, University of Cambridge, 2011
2011
-
[51]
Analyzing Internet-connected industrial equipment,
A. Hansson, M. Khodari, and A. Gurtov, “Analyzing Internet-connected industrial equipment,” in Proceedings of the 2018 International Confer- ence on Signals and Systems (ICSigSys ’18) . IEEE, 2018, pp. 29–35
2018
-
[52]
Vulnerability scanning of IoT devices in Jordan using Shodan,
H. Al-Alami, A. Hadi, and H. Al-Bahadili, “Vulnerability scanning of IoT devices in Jordan using Shodan,” in Proceedings of the 2017 2nd International Conference on the Applications of Information Technology in Developing Renewable Energy Processes & Systems (IT-DREPS ’17). IEEE, 2017
2017
-
[53]
A Large-Scale Empirical Study on the Vulnerability of Deployed IoT Devices,
B. Zhao, S. Ji, W.-H. Lee, C. Lin, H. Weng, J. Wu, P. Zhou, L. Fang, and R. Beyah, “A Large-Scale Empirical Study on the Vulnerability of Deployed IoT Devices,” IEEE Transactions on Dependable and Secure Computing, vol. 19, no. 3, pp. 1826–1840, 2022
2022
-
[54]
Online Discover- ability and Vulnerabilities of ICS/SCADA Devices in the Netherlands,
J. M. Ceron, J. J. Chromik, J. Santanna, and A. Pras, “Online Discover- ability and Vulnerabilities of ICS/SCADA Devices in the Netherlands,” arXiv:2011.02019, 2020
2011 arXiv
-
[55]
Peeking Under the Skirts of a Nation: Finding ICS Vulnerabilities in the Critical Digital Infrastructure,
T. Kiravuo, S. Tiilikainen, M. S ¨arel¨a, and J. Manner, “Peeking Under the Skirts of a Nation: Finding ICS Vulnerabilities in the Critical Digital Infrastructure,” in Proceedings of the 14th European Conference on Cyber Warfare and Security (ECCWS ’15) . ACPI, 2015, pp. 137–144
2015
-
[56]
ShoV AT: Shodan-Based Vulnerability Assessment Tool for Internet-Facing Services,
B. Genge and C. En ˘achescu, “ShoV AT: Shodan-Based Vulnerability Assessment Tool for Internet-Facing Services,” Security and Commu- nication Networks, vol. 9, no. 15, pp. 2696–2714, 2016
2016
-
[57]
Assessing the Use of Insecure ICS Protocols via IXP Network Traffic Analysis,
G. Barbieri, M. Conti, N. O. Tippenhauer, and F. Turrin, “Assessing the Use of Insecure ICS Protocols via IXP Network Traffic Analysis,” in Proceedings of the 2021 International Conference on Computer Communications and Networks (ICCCN ’21) . IEEE, 2021
2021
-
[58]
Towards automatic fingerprinting of IoT devices in the cyberspace,
K. Yang, Q. Li, and L. Sun, “Towards automatic fingerprinting of IoT devices in the cyberspace,” Computer Networks, vol. 148, pp. 318–327, 2019
2019
-
[59]
ZMap: Fast Internet- wide Scanning and Its Security Applications,
Z. Durumeric, E. Wustrow, and J. A. Halderman, “ZMap: Fast Internet- wide Scanning and Its Security Applications,” in Proceedings of the 22nd USENIX Security Symposium (SEC ’14) . USENIX Association, 2013, pp. 605–620
2013
-
[60]
Shodan, “Shodan,” https://www.shodan.io, 2013
2013
-
[61]
WebIoT: Classifying Internet of Things Devices at Internet Scale through Web Characteristics,
Y . Wu, C. Li, J. Yang, Z. Wang, W. Hu, A. Xia, Y . Jiang, Y . Wang, and L. Wu, “WebIoT: Classifying Internet of Things Devices at Internet Scale through Web Characteristics,” in Proceedings of the 2022 IEEE Symposium on Computers and Communications (ISCC ’22) . IEEE, 2022, pp. 1–7
2022
-
[62]
Centralized Zone Data Service,
Internet Corporation for Assigned Names and Numbers, “Centralized Zone Data Service,” https://czds.icann.org/home, 2020
2020
-
[63]
ZMapv6: Internet Scanner with IPv6 capabilities,
TU Munich – Chair of Network Architectures and Services, “ZMapv6: Internet Scanner with IPv6 capabilities,” https://github.com/tumi8/zmap, 2021
2021
-
[64]
ZGrab 2.0,
COMSYS, “ZGrab 2.0,” https://github.com/COMSYS/zgrab2, 2021
2021
-
[65]
The Menlo Report: Ethical Principles Guiding Information and Communication Technology Research,
D. Dittrich and E. Kenneally, “The Menlo Report: Ethical Principles Guiding Information and Communication Technology Research,” U.S. Department of Homeland Security, Tech. Rep., 2012
2012
-
[66]
Guidelines for the Selection, Config- uration, and Use of Transport Layer Security (TLS) Implementations,
K. A. McKay and D. A. Cooper, “Guidelines for the Selection, Config- uration, and Use of Transport Layer Security (TLS) Implementations,” NIST SP 800-52 Rev. 2, 2019
2019
-
[67]
Recommendations for Secure Use of Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS),
Y . Sheffer, R. Holz, and P. Saint-Andre, “Recommendations for Secure Use of Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS),” IETF RFC 7525, 2015
2015
-
[68]
Cryptographic Mechanisms: Recommendations and Key Lengths: Use of Transport Layer Security (TLS),
Federal Office for Information Security, “Cryptographic Mechanisms: Recommendations and Key Lengths: Use of Transport Layer Security (TLS),” BSI TR-02102-2, 2021
2021
-
[69]
TCP’s Initial Window—Deployment in the Wild and Its Impact on Performance,
J. R ¨uth, I. Kunze, and O. Hohlfeld, “TCP’s Initial Window—Deployment in the Wild and Its Impact on Performance,” IEEE Transactions on Network and Service Management , vol. 16, no. 2, pp. 389–402, 2019
2019
-
[70]
IPv6 Hitlists at Scale: Be Careful What You Wish For,
E. Rye and D. Levin, “IPv6 Hitlists at Scale: Be Careful What You Wish For,” in Proceedings of the 2023 ACM SIGCOMM Conference (SIGCOMM ’23). ACM, 2023, pp. 904–916
2023
Reviewed August 12, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.